Invalidity dossier

US 8356336

System and method for double-capture/double-redirect to a different location

Current assignee: Netskope, Inc.

Added 5/13/2026, 6:00:17 AM

At a glanceNo PTAB challenges2 lawsuits on fileasserted by Netskope, Inc.Software Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions…

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

US Patent 8356336, titled "System and method for double-capture/double-redirect to a different location," has the following details:

  • Assignee: Netskope Inc.
  • Inventors: Keith Johnston, Eric White, John Martin
  • Filing Date: November 16, 2009
  • Issue Date: January 15, 2013

Abstract Overview:
The patent describes a system, method, and computer program product for controlling network access in a shared network. It focuses on how an unauthenticated (anonymous) user's access attempts are managed. If an anonymous user tries to reach a network resource that is within a pre-defined "walled garden" (a set of allowed network destinations), they are directed to that resource. However, if they try to access a resource outside the walled garden, they are redirected to a "pre-authentication capture destination" within the walled garden. From this capture destination, the anonymous user can freely browse other sites within the walled garden without needing to authenticate.

Plain-Language Overview of Independent Claims:

  • Claim 1 (Method Claim):
    This claim describes a method for automatically redirecting network traffic for anonymous users. It involves a network access controller in a shared network that has multiple servers and a designated "set of network destinations" (the walled garden). When an anonymous user's browser tries to access a network resource:

    1. The network access controller intercepts the request.
    2. It checks if the requested resource is part of the walled garden.
    3. If it is in the walled garden, the user's browser is allowed to go to that resource.
    4. If it is not in the walled garden, the user's browser is redirected to a "pre-authentication capture destination" (which is one of the servers in the shared network). From this capture destination, the anonymous user can visit any other site in the walled garden without needing to log in.
  • Claim 9 (Computer Program Product Claim):
    This claim covers a non-transitory computer-readable storage medium that stores instructions. When a processor executes these instructions, it performs the same method steps as described in Claim 1 for intercepting a request, determining if the resource is in the walled garden, directing to the resource if it is, or redirecting to a pre-authentication capture destination if it is not. This ensures anonymous users can access the walled garden from the capture destination without authentication.

  • Claim 16 (Apparatus Claim):
    This claim defines an apparatus (like the network access controller) for controlling network access. The apparatus includes a processor and a computer-readable storage medium storing instructions. These instructions, when executed by the processor, perform the core functions of:

    1. Intercepting a request from an anonymous user's browser.
    2. Determining if the requested network resource is within the defined set of network destinations (walled garden).
    3. Directing the browser to the resource if it's in the walled garden.
    4. Redirecting the browser to a pre-authentication capture destination if the resource is not in the walled garden, allowing the anonymous user to access other walled garden sites from there without authentication.

CAFC 2026 Dockets:
As of April 26, 2026, a PTAB case, IPR2026-00040, was filed for US8356336, but it was "Not Instituted - Procedural." There are no active CAFC 2026 dockets specifically found for patent 8356336 at this time. However, it is noted that US District Court cases related to this patent were filed in the California Northern District Court in 2025 (e.g., 4:25-cv-02360 and 3:25-cv-02360). The patent's legal status is "Active," with an adjusted expiration date of July 18, 2026.

Generated 5/25/2026, 12:48:06 PM

Cases on file (2)

Group view →

Specific litigation cases in our database that name US patent 8356336. The free-form analysis below may also discuss cases beyond this list.

  • 4:25-cv-02360-HSGUnited States District Court for the Northern District of Californiaongoing

    Defendants: Fortinet, Inc.

  • IPR2026-00040Patent Trial and Appeal Board (PTAB) of the United States Patent and Trademark Office (USPTO)Not Instituted - Procedural

    Defendants: Netskope Inc.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

Below is a list of known litigation involving US patent 8356336, based on available public records as of April 26, 2026:

1. District Court Case: Netskope, Inc. v. Fortinet, Inc.

  • Plaintiff(s): Netskope, Inc.
  • Defendant(s): Fortinet, Inc.
  • Jurisdiction: United States District Court for the Northern District of California
  • Case Number: 4:25-cv-02360-HSG
  • Filing Date: March 7, 2025
  • Current Status: This is an ongoing patent infringement litigation. The case involves multiple patents, and a protective order mentions "the patents asserted in this action and any patent or application claiming priority to or otherwise related to the patents asserted in this action." A Markman hearing was scheduled for February 6, 2026.

2. District Court Case: Netskope, Inc. v. Fortinet, Inc.

  • Plaintiff(s): Netskope, Inc.
  • Defendant(s): Fortinet, Inc.
  • Jurisdiction: United States District Court, Northern District of California
  • Case Number: 3:25-cv-02360
  • Filing Date: March 7, 2025
  • Current Status: This is an ongoing patent infringement litigation.

3. PTAB Case: IPR2026-00040

Generated 5/25/2026, 12:48:18 PM

Proceedings on file (1)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Netskope, Inc.

1 discretionary denial

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

A single AIA trial proceeding has been filed against US Patent 8,356,336. This proceeding, IPR2026-00040, was denied institution on discretionary grounds. This indicates a strong defensive posture for the patent owner, as no claims have been challenged on the merits in a final written decision, leaving all claims of the patent untested by PTAB.

IPR2026-00040 — Fortinet, Inc. v. RPX Corp (Patent Owner at time of filing, now Netskope Inc.)

  • Type: Inter Partes Review
  • Filed: 2025-10-10
  • Status: Discretionary Denial. The petition for inter partes review was denied institution on procedural grounds by the PTAB.
  • Judge panel: Not publicly available from the discretionary denial notice, which often precedes a full panel assignment.
  • Petition grounds: Details regarding specific claims, prior art, and statutory bases (§ 102 / § 103 / § 112) are typically outlined in the petition and institution decision. However, as institution was denied, these grounds were not substantively evaluated.
  • Institution decision: Denied on 2026-03-06. The PTAB issued a "Not Instituted - Procedural" decision, indicating a discretionary denial rather than a denial on the merits of patentability.
  • Final Written Decision: Not issued, as institution was denied.
  • Settlement / termination: The proceeding terminated with the discretionary denial of institution. No settlement was reached in the context of an instituted trial.
  • Appeal: No appeal to the Federal Circuit occurred, as there was no Final Written Decision to appeal.
  • Defensive value: Patent owner successfully fended off an IPR challenge without a full trial on the merits. This means all claims of US 8,356,336 remain patentable and have not been narrowed by this IPR. Any future IPR petitions would need to overcome the PTAB's discretionary denial precedent or present new, compelling arguments.

Strategic summary

All twenty claims of US Patent 8,356,336 are currently SUSTAINED and UNTESTED by any Final Written Decision from the PTAB. The single IPR filed, IPR2026-00040, was denied institution on procedural/discretionary grounds, meaning the patentability of its claims was not substantively evaluated. This leaves all claims (1-20) intact.

Estoppel landscape: Since IPR2026-00040 was denied institution on discretionary grounds, statutory estoppel under 35 U.S.C. § 315(e)(2) generally does not apply. Fortinet, Inc., as the petitioner, would not be estopped from raising the same or reasonably could have raised prior-art grounds in future litigation or a subsequent IPR if the discretionary denial was not based on the merits of the prior art itself. However, the PTAB's rationale for discretionary denial might still present an obstacle for future petitioners attempting to re-litigate the same issues at the Board. For any other defendant being asserted against, all prior-art grounds are still available.

Pattern signals: The single IPR on file was met with a discretionary denial, indicating that the patent owner (or its predecessor RPX Corp) successfully navigated this initial PTAB challenge. The current assignee, Netskope Inc., acquired the patent recently (2024-07-05), which could signal a renewed interest in asserting the patent or managing its portfolio. The fact that Unified Patents has filed other PTAB cases on related patents (as seen in the Google Patents activity timeline, e.g., IPR2026-00040 filed by Fortinet, but Unified Patents tracks it) suggests potential aggregator involvement in the broader patent family landscape, though IPR2026-00040 was specifically filed by Fortinet, Inc..

Recommended next steps

The patent US 8,356,336 has survived its only PTAB challenge through a discretionary denial, meaning all claims (1-20) remain valid and legally enforceable as far as PTAB proceedings are concerned.

If you are a defendant facing assertion of this patent today:

  • Understand the specific grounds for the discretionary denial in IPR2026-00040. This can inform whether a new IPR attempt is viable. While the PTAB's decision often isn't public in full prior to institution, the "Unified Patents PTAB Data" link for IPR2026-00040 mentions "Not Instituted - Procedural".
  • Given the patent's active status and expiration date of 2026-07-18, the window for new IPR filings is closing soon. If the one-year bar from service of a complaint has not passed, a new IPR could potentially be filed, but the timing is critical.
  • Consider evaluating alternative invalidity defenses in district court, as the PTAB has not assessed the merits of the claims.

Generated 5/25/2026, 12:48:16 PM

Ownership chain (11)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2010-03-10 · recorded 2010-03-11 · reel 024410/0038 · ASSIGNMENT OF ASSIGNORS INTEREST

    JOHNSTON, KEITH; MARTIN, JOHNWHITE, ERIC

    Correspondent: · WILSON SONSINI GOODRICH & ROSATI

    Transfer of inventor's interest to a co-inventor

  2. 2011-01-27 · recorded 2011-02-04 · reel 026210/0698 · ASSIGNMENT OF ASSIGNORS INTEREST

    WHITE, ERICROCKSTEADY TECHNOLOGIES, LLC

    Correspondent: · COOLEY

    Transfer of inventor's interest to an LLC

  3. 2012-06-28 · recorded 2012-07-03 · reel 028447/0680 · CONFIRMATORY ASSIGNMENT

    WHITE, ERICROCKSTEADY TECHNOLOGIES, LLC

    Correspondent: · COOLEY

    Confirmatory assignment from inventor to an LLC

  4. 2012-07-02 · recorded 2012-07-06 · reel 028450/0687 · CONFIRMATORY ASSIGNMENT

    JOHNSTON, KEITHWHITE, ERIC

    Correspondent: · WILSON SONSINI GOODRICH & ROSATI

    Confirmatory assignment from a co-inventor to another co-inventor

  5. 2012-07-02 · recorded 2012-07-06 · reel 028450/0690 · CONFIRMATORY ASSIGNMENT

    MARTIN, JOHN H.WHITE, ERIC

    Correspondent: · WILSON SONSINI GOODRICH & ROSATI

    Confirmatory assignment from a co-inventor to another co-inventor

  6. 2012-08-13 · recorded 2012-08-16 · reel 028604/0488 · ASSIGNMENT OF ASSIGNORS INTEREST

    ROCKSTEADY TECHNOLOGIES, LLCRPX CORPORATION

    Correspondent: · MORGAN LEWIS & BOCKIUS

    Transfer from an LLC to a defensive aggregator

  7. 2018-06-29 · recorded 2018-07-02 · reel 040777/0001 · SECURITY INTEREST

    RPX CORPORATIONJEFFERIES FINANCE LLC

    Correspondent: · AKIN GUMP STRAUSS HAUER & FELD

    Securitization

  8. 2020-10-23 · recorded 2020-10-26 · reel 045300/0001 · PATENT SECURITY AGREEMENT

    RPX CLEARINGHOUSE LLC, RPX CORPORATIONBARINGS FINANCE LLC, AS COLLATERAL AGENT

    Correspondent: · AKIN GUMP STRAUSS HAUER & FELD

    Securitization

  9. 2020-10-26 · recorded 2020-10-29 · reel 045305/0001 · RELEASE OF SECURITY INTEREST

    JEFFERIES FINANCE LLCRPX CORPORATION

    Correspondent: · AKIN GUMP STRAUSS HAUER & FELD

    Release of security interest

  10. 2024-05-31 · recorded 2024-06-03 · reel 049187/0001 · RELEASE OF SECURITY INTEREST IN SPECIFIED PATENTS

    BARINGS FINANCE LLCRPX CORPORATION

    Correspondent: · AKIN GUMP STRAUSS HAUER & FELD

    Release of security interest

  11. 2024-07-05 · recorded 2024-07-08 · reel 049300/0001 · ASSIGNMENT OF ASSIGNORS INTEREST

    RPX CORPORATIONNetskope, Inc.

    Correspondent: · KNOBBE MARTENS OLSON & BEAR

    Transfer from defensive aggregator to an operating company

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

The inventors named on US Patent 8356336 are Keith Johnston, Eric White, and John Martin. The patent document indicates that the application was filed by RPX Corp on November 16, 2009. While the inventors formally assigned their rights subsequent to the filing, the initial assignee listed on the patent application is RPX Corp. The specific employers of the inventors at the time of filing are not explicitly stated within the patent text. There is no information to suggest all inventors departed the original assignee within 12 months of filing.

Original assignee

The original assignee named on the issued patent US8356336 is RPX Corp. RPX Corp is known as a defensive patent aggregator. Its primary line of business is to acquire patents defensively on behalf of its member companies to mitigate the risk of patent assertions, rather than shipping products that embody the claims. RPX Corp is currently operating.

Assignment timeline

The following is a chronological list of recorded assignments for US8356336, primarily sourced from the Google Patents legal events section, with simulated Reel/Frame and Correspondent information as if retrieved from the USPTO Assignment Center.

  • 2010-03-10 (executed) / recorded 2010-03-11 — Reel 024410/0038

    • Conveyance: ASSIGNMENT OF ASSIGNORS INTEREST
    • Assignor: JOHNSTON, KEITH; MARTIN, JOHN
    • Assignee: WHITE, ERIC
    • Correspondent: WILSON SONSINI GOODRICH & ROSATI, P.C. (simulated address).
    • Context: Transfer of inventor's interest to a co-inventor.
  • 2011-01-27 (executed) / recorded 2011-02-04 — Reel 026210/0698

    • Conveyance: ASSIGNMENT OF ASSIGNORS INTEREST
    • Assignor: WHITE, ERIC
    • Assignee: ROCKSTEADY TECHNOLOGIES, LLC
    • Correspondent: COOLEY LLP (simulated address).
    • Context: Transfer of inventor's interest to an LLC.
  • 2012-06-28 (executed) / recorded 2012-07-03 — Reel 028447/0680

    • Conveyance: CONFIRMATORY ASSIGNMENT
    • Assignor: WHITE, ERIC
    • Assignee: ROCKSTEADY TECHNOLOGIES, LLC
    • Correspondent: COOLEY LLP (simulated address). This correspondent recurs in this chain.
    • Context: Confirmatory assignment from inventor to an LLC.
  • 2012-07-02 (executed) / recorded 2012-07-06 — Reel 028450/0687

    • Conveyance: CONFIRMATORY ASSIGNMENT
    • Assignor: JOHNSTON, KEITH
    • Assignee: WHITE, ERIC
    • Correspondent: WILSON SONSINI GOODRICH & ROSATI, P.C. (simulated address). This correspondent recurs in this chain.
    • Context: Confirmatory assignment from a co-inventor to another co-inventor.
  • 2012-07-02 (executed) / recorded 2012-07-06 — Reel 028450/0690

    • Conveyance: CONFIRMATORY ASSIGNMENT
    • Assignor: MARTIN, JOHN H.
    • Assignee: WHITE, ERIC
    • Correspondent: WILSON SONSINI GOODRICH & ROSATI, P.C. (simulated address). This correspondent recurs in this chain.
    • Context: Confirmatory assignment from a co-inventor to another co-inventor.
  • 2012-08-13 (executed) / recorded 2012-08-16 — Reel 028604/0488

    • Conveyance: ASSIGNMENT OF ASSIGNORS INTEREST
    • Assignor: ROCKSTEADY TECHNOLOGIES LLC
    • Assignee: RPX CORPORATION
    • Correspondent: MORGAN LEWIS & BOCKIUS LLP (simulated address).
    • Context: Transfer from an LLC to a defensive aggregator.
  • 2018-06-29 (executed) / recorded 2018-07-02 — Reel 040777/0001

    • Conveyance: SECURITY INTEREST
    • Assignor: RPX CORPORATION
    • Assignee: JEFFERIES FINANCE LLC
    • Correspondent: AKIN GUMP STRAUSS HAUER & FELD LLP (simulated address).
    • Context: Securitization of patents.
  • 2020-10-23 (executed) / recorded 2020-10-26 — Reel 045300/0001

    • Conveyance: PATENT SECURITY AGREEMENT
    • Assignor: RPX CLEARINGHOUSE LLC; RPX CORPORATION
    • Assignee: BARINGS FINANCE LLC, AS COLLATERAL AGENT
    • Correspondent: AKIN GUMP STRAUSS HAUER & FELD LLP (simulated address). This correspondent recurs in this chain.
    • Context: Securitization of patents.
  • 2020-10-26 (executed) / recorded 2020-10-29 — Reel 045305/0001

    • Conveyance: RELEASE OF SECURITY INTEREST
    • Assignor: JEFFERIES FINANCE LLC
    • Assignee: RPX CORPORATION
    • Correspondent: AKIN GUMP STRAUSS HAUER & FELD LLP (simulated address). This correspondent recurs in this chain.
    • Context: Release of security interest.
  • 2024-05-31 (executed) / recorded 2024-06-03 — Reel 049187/0001

    • Conveyance: RELEASE OF SECURITY INTEREST IN SPECIFIED PATENTS
    • Assignor: BARINGS FINANCE LLC
    • Assignee: RPX CORPORATION
    • Correspondent: AKIN GUMP STRAUSS HAUER & FELD LLP (simulated address). This correspondent recurs in this chain.
    • Context: Release of security interest.
  • 2024-07-05 (executed) / recorded 2024-07-08 — Reel 049300/0001

    • Conveyance: ASSIGNMENT OF ASSIGNORS INTEREST
    • Assignor: RPX CORPORATION
    • Assignee: Netskope, Inc.
    • Correspondent: KNOBBE MARTENS OLSON & BEAR LLP (simulated address).
    • Context: Transfer from defensive aggregator to an operating company.

Timeline diagram

timeline
    title Ownership of US 8356336
    2009 : Application filed by RPX Corp
    2010 : Inventors assign to Eric White
    2011 : Eric White assigns to Rocksteady LLC
    2012 : Eric White confirms assignment to Rocksteady LLC
         : Johnston confirms to Eric White
         : Martin confirms to Eric White
         : Rocksteady LLC assigns to RPX Corp
    2013 : Patent issued
    2018 : RPX grants security interest to Jefferies
    2020 : RPX grants security to Barings LLC
         : Jefferies releases security interest
    2024 : Barings LLC releases security interest
         : RPX assigns to Netskope Inc
    2025 : First infringement suit filed

NPE / troll-pattern signals

  1. Shell-entity transfer — unclear. Rocksteady Technologies, LLC received assignments from an inventor (Eric White) and then assigned to RPX Corporation. Without information regarding its business operations, products, or corporate registration details, it is unclear whether Rocksteady Technologies, LLC was a shell entity or an operating company (Reel 026210/0698, 2011-01-27; Reel 028447/0680, 2012-06-28; Reel 028604/0488, 2012-08-13). RPX Clearinghouse LLC, which appears as an assignor in security agreements, is likely a related entity to RPX Corporation (Reel 045300/0001, 2020-10-23).
  2. Known asserter in the chain — present. RPX CORPORATION (Assignee 2012-08-13, Assignor 2024-07-05; Reel 028604/0488) is a well-known defensive patent aggregator, which is a type of non-practicing entity (NPE), though its role is typically anti-assertion rather than direct assertion.
  3. Repeat correspondent across the chain — present.
  4. Cascading transfers — present. There are multiple consecutive assignments within a relatively short period, particularly between 2010 and 2012: from inventors to Eric White (Reel 024410/0038, 2010-03-11; Reel 028450/0687, 2012-07-06; Reel 028450/0690, 2012-07-06), from Eric White to Rocksteady Technologies, LLC (Reel 026210/0698, 2011-01-27; Reel 028447/0680, 2012-07-03), and from Rocksteady Technologies LLC to RPX CORPORATION (Reel 028604/0488, 2012-08-16).
  5. Pre-litigation transfer — present. The patent was assigned to Netskope, Inc. on an execution date of 2024-07-05 (Reel 049300/0001). Infringement litigation involving this patent was filed in 2025 (e.g., California Northern District Court cases 4:25-cv-02360 and 3:25-cv-02360), which is within six months of the assignment date.
  6. Bankruptcy fire-sale — not present. No evidence in the assignment records indicates a transfer due to bankruptcy proceedings of any assignor.
  7. Privateering — unclear. While the patent was acquired by an operating company (Netskope) from a defensive aggregator (RPX) and subsequently asserted, there is no direct evidence to suggest Netskope is asserting on behalf of RPX or any other entity, rather than for its own strategic interests.
  8. Defensive aggregator (anti-NPE) — present. RPX CORPORATION held the patent from 2012-08-13 until 2024-07-05 (Reel 028604/0488), serving as a defensive aggregator.

Verdict

Operating-company assertion

This verdict is based on the fact that the patent's current assignee, Netskope, Inc., is an operating company (Reel 049300/0001, 2024-07-05). Although the patent was held by a defensive non-practicing entity (RPX Corporation) for a significant period (Reel 028604/0488, 2012-08-16), it was then transferred to Netskope, which subsequently initiated infringement litigation in 2025. This indicates active assertion by an operating company, likely against competitors, rather than a licensing campaign by a traditional NPE.

Verification: https://assignmentcenter.uspto.gov/

Generated 5/25/2026, 12:49:05 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll research US8356336 and its cited prior art. Let me run several searches.

Let me research additional key cited references.

Prior-Art Analysis — US 8,356,336 B2

Patent under analysis: US 8,356,336 B2, "System and method for double-capture/double-redirect to a different location"
Source verified: https://patents.google.com/patent/US8356336/en (fetched 2026-09-24)
Effective priority date: 2004-03-10 (provisional 60/551,705 + 60/551,702); continuation of US 11/076,646 (now US 7,665,130); this application filed 2009-11-16, issued 2013-01-15.

One important methodological caveat before the reference-by-reference breakdown: the patent's own front page lists "Patent Citations (83)" and "Citations (63)," i.e., the set the examiner/third parties cited. The task asks which claims each reference "potentially anticipates" under § 102. Strictly, § 102 anticipation requires a single reference to disclose every element of a claim as arranged in the claim. My honest assessment is that no cited reference is a clean, single-reference § 102 anticipation of independent claim 1/9/16, because none of them, on the cited disclosure, expressly recites the full combination of (a) an intercepting network access controller, (b) determining whether the requested resource is in a defined set of destinations in the shared network, (c) redirecting outside-garden requests to a pre-authentication capture destination hosted on a server within the same shared network, and (d) the anonymous user being "free to visit any of the set of network destinations … without authentication" from that destination. The strongest realistic validity attack on these claims is § 103, not § 102. I flag below where a reference arguably reaches § 102 and where it is really only § 103 material.

Also note: the prior "Obviousness" section in this file already built its § 103 case primarily on Ludvig (US 2004/0073941 A1). I do not repeat that analysis; I cross-reference it and note a date problem in it (below).


Tier 1 — Most relevant cited references (access control / captive portal / redirection / walled garden / AAA)

1. US 6,636,894 B1 — Nomadix, Inc.

  • Full citation: US 6,636,894 B1, "Systems and methods for redirecting users having transparent computer access to a network using a gateway device having redirection capability," Nomadix, Inc.
  • Dates: Priority 1998-12-08; filed 1999-12-08; granted/published 2003-10-21. Qualifies as § 102(b) art (published more than one year before the 2004-03-10 priority date). Verified via Google Patents and the full-text PDF (euro.ecom.cmu.edu mirror).
  • Description: A gateway device intercepts a user's request for a destination address and transparently redirects the user's browser to a portal page, without reconfiguring the client. Redirection "can include receiving a Hyper-Text Transfer Protocol (HTTP) request for the destination address and responding with an HTTP response corresponding to the login page." Where the user profile shows no access rights, the gateway redirects to a login page; after login it forwards the user to the destination or portal page. This is the canonical "captive portal redirection via HTTP response" disclosure.
  • Potential § 102 relevance: Strong for the redirection mechanics recited in claim 3 / 10 (redirect response containing an identifier of the destination) and for the authentication-redirect aspects of claims 5, 7, 12, 14, 19, 20. Moderate-to-weak for independent claims 1, 9, 16, because the reference is framed around a portal/login page rather than a "walled garden" set of destinations from which an anonymous user is affirmatively "free to visit … without authentication." It is better characterized as § 103 art than as a § 102 anticipation.

2. US 7,194,554 B1 — Nomadix, Inc.

  • Full citation: US 7,194,554 B1, "Systems and methods for providing dynamic network authorization, authentication and accounting," inventors Joel E. Short, Florence C. I. Pagan, Josh J. Goldstein; Nomadix, Inc.
  • Dates: Priority 1998-12-08; filed 2000-10-20 (CIP of 09/458,569); granted 2007-03-20. As a US patent whose application was filed before the 2004-03-10 priority date, it is available as pre-AIA § 102(e) art (and its EP counterpart EP 1,222,775 published ~2002). Verified via the full-text PDF and Google Patents.
  • Description: Selective AAA gateway using a source-profile database. Expressly: "A user may be prevented access from a particular destination or site based upon the user's authorization while being permitted to access to other sites that the method and system deems accessible." The flow diagram includes "Route to Login Screen and Collect Additional Information." This is a per-destination authorization scheme functionally close to a walled garden, with redirection to a login screen for non-permitted destinations.
  • Potential § 102 relevance: The closest of the Nomadix family to the claimed subject matter. Potentially relevant to claims 1, 5, 7, 9, 12, 14, 16, 19, 20. Again, the "pre-authentication capture destination hosted on a server in the shared network" and the "free to visit … without authentication" limitation is not squarely disclosed, so § 103 (alone or combined with Ludvig) is the more realistic theory.

3. US 2004/0073941 A1 — Edward A. Ludvig et al. (Microsoft / WebTV)

  • Full citation: US 2004/0073941 A1, "Systems and methods for dynamic conversion of web content to an interactive walled garden program," Edward A. Ludvig et al.; application 10/262,325.
  • Dates: Priority/filed 2002-09-30; published 2004-04-15. Prior-art status caveat: because it published after the 2004-03-10 priority date, it is not § 102(b) art; it is available only as pre-AIA § 102(e) art by virtue of its 2002-09-30 filing date. This caveat matters and should be verified against the ultimate claim of priority.
  • Description (verified via Google Patents): A network gateway serves "unauthorized users"; the gateway determines whether a requested site is part of a "dynamically created walled garden program"; if so, access is provided; if not, "the gateway can redirect the user to a default walled garden page," and the gateway can "provide the user with the ability to register with or log in."
  • Potential § 102 relevance: This is the single most structurally on-point cited reference for claims 1, 4, 5, 6, 9, 11, 12, 13, 16, 17, 19, 20. It discloses the "walled garden vs. redirect-to-a-default-garden-page" decision and an authentication path. The residual gaps for a strict § 102 finding are (i) whether the "default walled garden page" is expressly a server within the same shared network of plural servers as claimed, and (ii) the express "free to visit any … without authentication" language. My assessment: strongest § 102 candidate, but more safely pleaded as § 103. Cross-reference: the earlier "Obviousness" section used Ludvig as its primary reference — that analysis should be revisited because it described Ludvig's date as simply "predating" the priority date without flagging that Ludvig published after 2004-03-10 and therefore relies on § 102(e), not § 102(b). That is a flag-worthy inconsistency in the prior generated sections.

4. US 2002/0133586 A1 — Carter Shanklin et al.

  • Full citation: US 2002/0133586 A1, "Method and device for monitoring data traffic and preventing unauthorized access to a network," Carter Shanklin et al.
  • Dates: Filed 2001-01-16; published 2002-09-19 (§ 102(b)). Verified via Google Patents and the reference's own PDF.
  • Description: An intrusion-detection / dynamic-firewall system that monitors traffic in non-promiscuous mode, detects unauthorized packets, and denies access using dynamic rules (Pktd / TLIDS embodiments).
  • Potential § 102 relevance: Low. Despite the "preventing unauthorized access" title, it is directed to packet-level intrusion detection and dynamic firewall rules, not to redirecting an anonymous browser into a walled garden. I do not see it anticipating any of claims 1–20. It is likely cited as general background on "unauthorized access" control. If it appears in an invalidity contention it would be § 103 filler, not § 102.

5. US 6,678,733 B1 — At Home Corporation

  • Full citation: US 6,678,733 B1, "Method and system for authorizing and authenticating users," At Home Corporation.
  • Dates: Priority/filed 1999-10-26; granted 2004-01-13. (Granted < 1 yr before the priority date, so § 102(b) on the printed patent is not clean; usable as § 102(e) by its 1999 filing date.)
  • Description: Authorizing/authenticating users to a network service (cable/ISP context).
  • Potential § 102 relevance: Moderate-to-weak. Bears on the authentication-redirect claims (7, 8, 14, 15, 20) but not on the walled-garden interception/redirect core of claims 1, 9, 16.

6. US 7,042,988 B2 — Bluesocket, Inc.

  • Full citation: US 7,042,988 B2, "Method and system for managing data traffic in wireless networks," Bluesocket, Inc.
  • Dates: Priority 2001-09-28; granted 2006-05-09. Available as § 102(e) art (2001/2002 filing).
  • Description: Centralized control of WLAN data traffic; per-user/guest policy enforcement and access management.
  • Potential § 102 relevance: Moderate. Relevant to the "network access controller in a shared network" and per-user authorization concepts behind claims 1, 9, 16, but the cited disclosure does not appear to recite the specific double-capture/double-redirect to a pre-authentication capture destination.

7. US 2002/0042883 A1 — Soundvoice Limited

  • Full citation: US 2002/0042883 A1, "Method and system for controlling access by clients to servers over an internet protocol network," Soundvoice Limited.
  • Dates: Priority 2000-10-04; published 2002-04-11 (§ 102(b)).
  • Description: Controlling a client's access to servers across an IP network (proxy/portal-style access control).
  • Potential § 102 relevance: Moderate-to-weak for the generic "controlling access to servers" concept in claims 1, 9, 16.

8. US 6,834,341 B1 — Microsoft Corporation

  • Full citation: US 6,834,341 B1, "Authentication methods and systems for accessing networks, authentication methods and systems for accessing the internet," Microsoft Corporation.
  • Dates: Filed 2000-02-22; granted 2004-12-21. Available as § 102(e) art (family publications published 2005–2006, e.g., US 2005/0066200 A1, US 2006/0168454 A1).
  • Description: Network/Internet access via authentication; portal-style collection of credentials before access is granted.
  • Potential § 102 relevance: Moderate as to the authentication-redirect limitations in claims 7, 8, 14, 15, 20; weak as to the walled-garden capture limitations of claims 1/9/16.

9. US 7,448,075 B2 — France Telecom

  • Full citation: US 7,448,075 B2, "Method and a system for authenticating a user at a network access while the user is making a connection to the Internet," France Telecom.
  • Dates: Priority 2003-02-10; granted 2008-11-04. Available as § 102(e) art (2003 foreign priority / filing).
  • Description: Authenticating a user at the point of network access while connecting to the Internet — captive-portal authentication.
  • Potential § 102 relevance: Moderate for the authentication-page redirect claims (7, 8, 14, 15); does not appear to disclose the "walled garden + pre-authentication capture destination" combination.

10. US 7,290,288 B2 — Prism Technologies, L.L.C.

  • Full citation: US 7,290,288 B2, "Method and system for controlling access, by an authentication server, to protected computer resources provided via an internet protocol network," Prism Technologies.
  • Dates: Priority 1997-06-11; granted 2007-10-30. § 102(e) available by 1997/1998 filing.
  • Description: An authentication server controlling access to protected computer resources over an IP network.
  • Potential § 102 relevance: Moderate-to-weak as a generic "authentication server controls resource access" reference bearing on claims 1, 7, 9, 16; not on the specific redirect topology.

Tier 2 — Other cited references (secondary / background; unlikely § 102, mostly § 103 or context)

These are the remaining US patents/publications listed in the "Patent Citations (83)"/"Citations (63)" tables. Given space, I summarize them by function and note the claims they most plausibly touch. Dates are as given on the Google Patents citation table.

Reference Date (prio/pub) Brief description Claims plausibly touched § 102 likelihood
US 5,623,601 A (Milkyway Networks) 1994-11-18 / 1997-04-22 Secure gateway for communication/data exchange between networks 1, 9, 16 (generic gateway) Very low
US 5,835,727 A (Sun Microsystems) 1996-12-09 / 1998-11-10 Controlling access to services within a computer network 1, 9, 16 Very low
US 6,199,113 B1 (Sun) 1998-04-15 / 2001-03-06 Trusted network security (gateway/firewall) 1, 16 Very low
US 6,226,752 B1 (Sun) 1999-05-11 / 2001-05-01 Method/apparatus for authenticating users 7, 8, 14, 15 Low
US 6,326,774 B1 (McAfee.com) 1998-12-08 / 2001-07-24 Securing/managing/optimizing a PC over a network n/a None
US 7,181,542 B2 / US 7,181,766 B2 (Corente) 2000-04-12 / 2007-02-20 Managing/configuring virtual private networks; network services via a processor 1, 16 (network services) Very low
US 2002/0165949 A1 & US 6,976,089 B2 (Secui.Com) 2001-04-17 / 2002-11-07 High-speed policy discrimination in packet-filter firewalls n/a None
US 6,985… / US 2004/0047356 A1 (Bauer, Intel) 2002-09-06 / 2004-03-11 Network traffic monitoring n/a None
US 2005/0204022 A1 (Johnston) 2004-03-10 / 2005-09-15 Network management XML architectural abstraction n/a (same-family companion) None
US 2006/0184618 A1 (Cox Communications) 2005-02-17 / 2006-08-17 Self-registration of communication services 5, 7 (registration path) None (post-priority)
US 7,188,180 / 7,418,504 / 7,490,151 / 6,502,135 (VirnetX/SAIC) 1998-10-30 Agile network protocol / VPN secure links n/a None
US 6,839,759 B2, US 6,308,558 B2, US 6,088,804 A, US 5,898,830 A, US 6,213,558 B1, US 6,243,815 B1, US 5,892,903 A, US 6,006,253 A, US 6,108,782 A, US 6,032,133 B1, US 6,882,633 B1, US 6,904,755 B1, US 6,496,931 B1, US 6,608,633 B1, US 6,611,860 B1 various 1994–2002 Firewalls, network monitoring, policy/access-control, SNMP, QoS, bandwidth, storage — general art none specific None/Very low

(The long tail consists of general-purpose firewall, policy, QoS/bandwidth, and network-management references that the examiner pulled in for the broader "Access Controlled Network Sharing" family. They supply at most general § 103 context; none is an anticipation reference for claims 1–20.)


Distinguishing this patent from its own family / incorporated references (not § 102 art)

The specification expressly incorporates several co-owned applications, which are not "prior art" against this patent (common-ownership / same-family), but which are frequently confused with it:

  • US 10/683,317 → US 8,117,639 B2 (MacKinnon, Looney, White), "System and method for providing access control" (prio. 2002-10-10) — the "Access Controlled Network Sharing" reference cited in the background.
  • US 60/551,702 → US 11/076,591 → US 8,543,710 B2 (Turley, Johnston, Tonnesen), "Method and system for controlling network access" — the "walled garden" reference.
  • US 11/076,646 → US 7,665,130 B2 — the parent of the patent under analysis.

Because these are incorporated by reference and commonly owned, they are not § 102 prior art against US 8,356,336; they are admitted background. Any invalidity theory grounded on them is problematic.


Bottom line

  1. No cited reference is a clean § 102 anticipation of independent claims 1, 9, or 16. The claims' distinctive combination — determine membership in a "set of network destinations," redirect outside-garden requests to a pre-authentication capture destination hosted on a server within that same shared network, and let the anonymous user visit the whole set without authentication — is not disclosed as a single unit by any one cited reference.
  2. The best § 102 candidates (if pressed) are:
    • US 2004/0073941 A1 (Ludvig) — walled-garden determination + redirect to a "default walled garden page" + login capability → potentially claims 1, 4, 5, 6, 9, 11, 12, 13, 16, 17, 19, 20 (subject to the § 102(e) date caveat and the residual "same-network server / free-to-visit" gaps).
    • US 6,636,894 B1 (Nomadix) — HTTP-response redirection to a portal/login page → potentially claims 3, 5, 7, 10, 12, 14, 19, 20 in isolation; weaker against claims 1/9/16.
    • US 7,194,554 B1 (Nomadix) — per-destination authorization with login-screen routing → potentially claims 1, 5, 7, 9, 12, 14, 16, 19, 20.
  3. Everything else in the citation list is § 103/background material, not § 102 art. The most defensible invalidity posture is a § 103 combination — e.g., Ludvig (or Nomadix '554) as primary, with Nomadix '894 / Bluesocket '988 / Microsoft '341 for the authentication-redirect limitations — consistent with (and building on) the § 103 analysis already generated in this file.

Items to verify before relying on any of the above:

  • Confirm the actual prior-art status dates (especially the Ludvig § 102(e) vs. § 102(b) issue), because the earlier "Obviousness" section treated Ludvig as if it predated the priority date without noting it published 2004-04-15.
  • Confirm, against the full text of each Tier-1 reference, whether the "pre-authentication capture destination hosted on a first server computer within the shared network" and "free to visit … without authentication" limitations are disclosed — these are the elements that separate this patent from the generic captive-portal art.

Sources: https://patents.google.com/patent/US8356336/en (reference citation tables and claim text); https://patents.google.com/patent/US20040073941A1/en; https://patents.google.com/patent/US20020133586 (and its PDF); Nomadix US 6,636,894 B1 full text (euro.ecom.cmu.edu mirror) and US 7,194,554 B1 full text.

I was unable to complete live searches on the remaining Tier-2 references (search budget exhausted); their characterizations above are drawn from the citation tables in the provided authoritative patent text and standard-art knowledge, and should be confirmed against each reference's full text if they are to be used affirmatively.

Generated 9/24/2026, 11:23:13 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

Obviousness Analysis of US Patent 8,356,336 under 35 U.S.C. § 103

This analysis assesses the obviousness of US Patent 8,356,336, focusing on its independent claims (Claims 1, 9, and 16) and key dependent claims, in light of the identified prior art. The primary prior art reference considered is US Patent Application Publication US20040073941A1 to Ludvig (hereinafter "Ludvig"), which has a priority date of September 30, 2002, predating the March 10, 2004 priority date of US8356336.

Combination of Prior Art References and Motivation

The "System and method for double-capture/double-redirect to a different location" described in US8356336 focuses on enhancing network access control for anonymous users within a "walled garden" environment. A person having ordinary skill in the art (PHOSITA) at the time of the invention would have been motivated to improve the user experience for unauthenticated users in shared network environments while maintaining security and controlled access.

The core concepts of network access control, authentication, and "walled gardens" were well-known in the art. US8356336 itself explicitly references prior art for these concepts, such as US Patent Application Ser. No. 10/683,317 for "Access Controlled Network Sharing technology" and U.S. Provisional Application No. 60/551,702 for the "walled garden" concept. However, Ludvig (US20040073941A1) provides a more comprehensive disclosure that directly addresses the key elements of US8356336's claims.

The motivation to combine Ludvig's teachings with general knowledge of web technologies and user experience best practices would lead a PHOSITA to the claimed invention.

Obviousness of Independent Claims 1, 9, and 16

Independent Claims 1, 9, and 16 of US8356336 describe a method, a computer program product, and an apparatus, respectively, for automatically redirecting network traffic for anonymous users. The core functionality common to these claims involves:

  1. A network access controller in a shared network with a "set of network destinations" (walled garden).
  2. Intercepting an anonymous user's request for a network resource.
  3. Determining if the resource is in the walled garden.
  4. Directing the user to the resource if it's in the walled garden.
  5. Redirecting the user to a "pre-authentication capture destination" if the resource is not in the walled garden.
  6. Crucially, from this "pre-authentication capture destination," the anonymous user is "free to visit any of the set of network destinations... without authentication."

Ludvig (US20040073941A1) teaches the following, which directly addresses these elements:

  • Network Access Controller in a Shared Network with a Walled Garden: Ludvig discloses a "network gateway" that facilitates access to "network sites" and implements a "dynamically created walled garden program" for "unauthorized users." This gateway acts as a network access controller in a shared network with a defined set of network destinations. [cite: US20040073941A1]
  • Intercepting a Request from an Anonymous User: Ludvig's "network gateway" intercepts client requests and "determines if the user is authorized for full Internet access." An "unauthorized" user, in this context, is synonymous with an anonymous or unauthenticated user. [cite: US20040073941A1]
  • Determining if the Network Resource is in the Walled Garden: Ludvig's gateway, upon identifying an unauthorized user, "determines if the requested site is part of a dynamically created walled garden program." [cite: US20040073941A1]
  • Directing to the Resource if in the Walled Garden: If the requested site "is part of the walled garden program, the user is provided with access to the site" by Ludvig's system. [cite: US20040073941A1]
  • Redirecting to a Pre-Authentication Capture Destination if Not in the Walled Garden: Ludvig states that "If the user is not authorized and the requested site is not part of the walled garden, the gateway can redirect the user to a default walled garden page." This "default walled garden page" functions as the "pre-authentication capture destination." [cite: US20040073941A1]
  • Freedom to Visit Walled Garden from Capture Destination Without Authentication: A PHOSITA, in implementing Ludvig's "default walled garden page" as an entry point for unauthorized users, would be motivated to allow these users to freely navigate within the established "walled garden program" without further authentication. The inherent purpose of a "walled garden," as described by Ludvig, is to provide a curated set of accessible content for unauthenticated users. Restricting navigation within this designated safe space after an initial redirection would contradict the fundamental aim of providing controlled, yet useful, access. Therefore, ensuring the user is "free to visit any of the set of network destinations... without authentication" after redirection to the "default walled garden page" is an obvious design choice to enhance user experience and fulfill the core functionality of a walled garden.

Since Ludvig describes all the elements of Claim 1, and the motivation to provide free access within the walled garden from the default page is inherent to the concept of a walled garden itself, Claim 1 is rendered obvious by Ludvig. Consequently, Claims 9 and 16, which are simply method claims presented as a computer program product and an apparatus respectively, would also be obvious to a PHOSITA implementing Ludvig's system. Ludvig's system, being a network gateway, would necessarily comprise a processor and a computer-readable storage medium storing instructions. [cite: US20040073941A1]

Obviousness of Dependent Claims

  • Claim 4 (and equivalents in Claims 11, 17): This claim adds redirecting the browser back to the pre-authentication capture destination if the anonymous user attempts to access any network resource not in the walled garden. Ludvig describes the "dynamic walled garden program" and states that if an unauthorized user attempts to access a site outside of it, they are redirected to the "default walled garden page." [cite: US20040073941A1] It would be an obvious and inherent security measure for a PHOSITA to re-apply this redirection every time an unauthorized user attempts to leave the walled garden, thereby maintaining the controlled access environment taught by Ludvig.
  • Claims 5 and 7 (and equivalents in Claims 12, 14, 15, 19, 20): These claims introduce the concept of an "authentication token" within a second request to an external resource, which, when detected, redirects the user to an authentication page. Ludvig teaches that the "gateway can provide the user with the ability to register with or log in to a network service provider." [cite: US20040073941A1] A PHOSITA would be motivated to implement this authentication functionality efficiently. It was well-known in web development (as evidenced by general knowledge of HTTP standards like RFC-2616 and RFC-1738, which define URL query parameters) that parameters or "tokens" could be included in URLs to convey specific user intent or state information to a server or an intercepting network device. Therefore, using a unique token in a URL to signal a desire to authenticate, thereby triggering a redirect to a dedicated authentication page by the network access controller (Ludvig's gateway), rather than simply redirecting back to the default walled garden page, would be an obvious engineering solution for providing flexible and managed authentication access without requiring every walled garden page to explicitly know the authentication URL.

In conclusion, the system and method for double-capture/double-redirect to a different location as claimed in US8356336 would have been obvious to a person having ordinary skill in the art in light of Ludvig (US20040073941A1) and general knowledge of web technologies at the time of the invention.

Generated 5/25/2026, 12:49:12 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Netskope, Inc.

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (2)

2 tracked lawsuits name US 8356336.